Splunk Search

How to display multiple search values as search coumns in the search table

kodali21055
New Member

Hi,

My application has lot of error codes(all most 35) which logs in the log file. I want to get count of each error code from the log file. For that I have written the rex as
rex "(?\d+)" | chart count by DIID, cbs2_error_code
Which is giving the out put till only 10 error codes and rest of them comes under OTHER

For eg:
20009 21002 21003 21999 25002 25017 25100 25107 25111 25113 OTHER
20 35 5 8 10 14 20 12 11 10 40

But I have lot of other error codes like 10001, 10002, 10003,.. which all are come under OTHER

Can some one help me how best I can get the report with count of each error code in the log file?

Thanks In Advance

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...